Insufficient Input Validation in NetScaler ADC and Gateway by Citrix
CVE-2026-8451

8.8HIGH

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
30 June 2026

What is CVE-2026-8451?

This vulnerability arises from inadequate input validation processes within Citrix's NetScaler ADC and NetScaler Gateway when they are configured as a SAML Identity Provider (IDP). Attackers may exploit this weakness, leading to potential memory overreads. Proper configuration and security patches should be applied to mitigate the risks associated with this vulnerability.

Affected Version(s)

ADC 14.1 < 72.61

ADC 13.1 < 63.18

ADC 14.1 FIPs < 72.61

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.